As enterprises move from generative AI assistants to agents that can take action, security teams are being forced to rethink what authorisation means. F5’s announced Workforce AI Security product is built around a useful phrase for the problem: 'borrowed authority'.

An AI agent may be able to access an enterprise system, retrieve data or invoke a tool because it is operating under permissions granted to a human user. The user may be properly authenticated, but that does not automatically mean every action generated by the agent should be permitted.

F5 says Workforce AI Security is due to begin general availability in October 2026. The company says that, upon availability, expected capabilities include inspecting and classifying agent tool calls - including calls through Model Context Protocol connections - and applying policy based on identity, access risk and sensitive-data exposure.

Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.

The Model Context Protocol, or MCP, is an open protocol for connecting AI applications and agents to external tools and data sources. Its usefulness is also what creates the security challenge. Once an agent can reach enterprise services through tools, prompt-level controls are no longer enough. Security policy has to follow the action.

The core question becomes more specific than 'is this user authenticated?'. It is closer to: is this agent authorised to perform this particular action, using this user’s authority, against this system, with this data, at this moment? That requires context from identity systems, tool permissions, data classification and runtime security controls.

The borrowed-authority problem also illustrates why agent governance and cyber security are converging. An organisation needs an inventory of the agents it has allowed into production, a way to associate them with owners, clear limits on what they can do and evidence of the actions they take. Without those elements, an AI governance policy can describe acceptable behaviour without providing a mechanism to enforce it.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

For regulated businesses, the issue becomes even more important when agents touch customer data, financial transactions, claims, trading systems or other sensitive workflows. A legitimate user can accidentally or deliberately instruct an agent to do something that exceeds the intended purpose of their access. The control point therefore needs to consider the action, not just the identity behind the session.

F5’s announcement is part of a broader market shift toward runtime controls for agentic AI. The strategic question for enterprises is how these new controls will integrate with existing identity, data security and application security tools rather than becoming another standalone layer that security teams have to manage separately.


Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.
Share this post
The link has been copied!